Supply chain β›“ Supply Chain

BORN Ontario Third-Party Breach (September 2023)

πŸ“… 2023-09-01 🏒 Ipswitch, Inc.
Primary Source β†—

Incident Details

SickKids impacted by BORN Ontario data breach that hit 3.4 million. The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. The top Canadian pediatric hospital disclosed that as a part of its operations, it shares personal health information with BORN Ontario “related to pregnancy, birth and newborn care.”. The BORN Ontario data breach that impacted 3.4 million people was caused by the exploitation of well-known zero-day vulnerability ( CVE-2023-34362 ) in Progress MOVEIt Transfer software. On Monday, September 25th, SickKids disclosed that it is “among the many Ontario healthcare providers” that share sensitive health information with BORN Ontario, a perinatal and child registry that collects, interprets, shares and protects critical data about pregnancy, birth and childhood in the province of Ontario. Third-party company: Ipswitch, Inc..

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Ipswitch, Inc.
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-09-01 Breach occurred
  2. 2023-09-26 Publicly disclosed